Data breach
MySpace
- Records
- 358,769,851
- Breach date
- 1 July 2008Estimated
- Added
- 1 December 2024
What was exposed
2 types of data · 1 more reported · 1 puts you at serious risk
- Email addresses358,769,851
- Passwords356,219,378
- UsernamesReported, not counted
Reported in the breach write-up; not counted in the analysed data.
About this breach
In one of the largest credential exposures ever indexed, the investigation team estimates that 358,769,851 accounts tied to MySpace, the once-dominant social network, were compromised in an attack estimated to have taken place around July 1, 2008. The stolen data surfaced publicly years later: in late May 2016, a data breach search engine reported that a massive cache of MySpace email addresses and passwords was being sold on a dark web marketplace. According to TechTimes, the seller, a hacker using the alias "Peace," listed the records for 6 bitcoin, roughly $2,800 at the time. MySpace later confirmed the breach in a statement, attributing it to the same actor and noting the stolen logins came from accounts created on the old platform before its June 11, 2013 relaunch.
May 27, 2016: LeakedSource, a searchable repository of leaked records, reported it had obtained a MySpace data set containing roughly 360 million records, per TechTimes.
May 31, 2016: MySpace published a statement on its blog confirming that stolen user login data had been made available in an online hacker forum and that it had begun invalidating affected passwords.
What Information Was Compromised?
Our analysis found the following data types in this breach: 358,769,851 email addresses and 356,219,378 passwords, according to the investigation team.
MySpace's own statement, published on its blog, said the exposed information also included MySpace usernames for affected accounts. The company emphasized that it does not collect or store credit card or financial information, so no user financial data was involved in the incident.
Not every individual is affected by every type of data listed here.
Reporting at the time also noted the passwords were protected with weak, outdated hashing, leaving many of them vulnerable to decryption. Fraud.org put the total at roughly 427 million passwords and about 360 million email addresses.
What Are the Potential Risks for Affected Individuals?
Because the exposure consists almost entirely of email addresses and passwords, the main risks are credential-related:
Password reuse. Many people reuse the same password across services. Anyone who used their MySpace password elsewhere should assume attackers may try it on email, banking, or shopping accounts.
Credential stuffing. Criminals routinely feed large leaked email-and-password lists into automated login attempts against other websites.
Phishing and spam. With hundreds of millions of valid email addresses in circulation, exposed users are likely targets for fraudulent emails designed to harvest more credentials or personal information.
The breach predates modern password storage practices, and MySpace itself noted in 2016 that the compromised data came from accounts created before the security upgrades introduced at the June 2013 site relaunch.
What Is MySpace Doing in Response?
In its May 31, 2016 statement, MySpace said it had invalidated all user passwords for affected accounts created before June 11, 2013 on the old platform, forcing returning users to authenticate and reset their passwords. The company said it was using automated tools to identify and block suspicious account activity, had reported the incident to law enforcement, and was cooperating with the investigation. It also pointed users to its password reset page and encouraged anyone reusing their MySpace password elsewhere to change those passwords immediately.
What Should You Do If You Were Affected?
If you had a MySpace account, especially one created before June 11, 2013, reset the password if you still use the site, or simply delete the account if you no longer need it.
Do not reuse passwords across sites. If your MySpace password was used anywhere else, change those passwords now, starting with email and financial accounts.
Enable two-factor authentication wherever it is offered.
Watch for phishing emails that reference MySpace or ask you to "verify" an account, and never enter credentials through links in unsolicited email.
